VALLEYWISE HEALTH EHR ACCESS AGREEMENT.PDF
Extracted text (via pymupdf)
30573 characters
1
AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION
IN THE
VALEYWISE HEALTH ELECTRONIC HEALTH RECORDS SYSTEM
THIS AGREEMENT for Access to Valleywise Health Valleywise Health’s Protected Health Information (“PHI”)
(“Agreement”) is entered into effective as of the 18th day of May, 2022 (“Effective Date”) between Maricopa County
Special Health Care District d.b.a. Valleywise Health (hereinafter “Valleywise Health”) and the Maricopa County by
and through its Department of Public Health (MCDPH), Office of Epidemiology (“External Entity”) and
(collectively referred to as “Parties”).
WHEREAS, Valleywise Health utilizes certain systems which allow authorized users to remotely access Valleywise
Health patient electronic health records (“Valleywise Health EHR System”) that are maintained by and within
Valleywise Health, including those providers who are members of Valleywise Health’ Medical Staff and such other
health care providers contractually affiliated with Valleywise Health.
WHEREAS, the Valleywise Health EHR System has the capacity to allow these parties to view Valleywise Health’
electronic health records (“EHR”) of Valleywise Health patients for the purpose of treatment, payment, and certain health
care operations to the extent permitted without authorization by the Administrative Simplification subtitle of the Health
Insurance Portability and Accountability Act of 1996, and the rules and regulations promulgated thereunder, as may be
amended from time to time (collectively, “HIPAA”), and further subject to the American Recovery and Reinvestment
Act of 2009 (“ARRA”), including its provisions Health Information Technology for Economic and Clinical Health Act
( “HITECH Act,”) and rules and regulations promulgated thereunder, as may be amended from time to time; and,
WHEREAS, Valleywise Health believes that the use of the Valleywise Health EHR System by External Entity would
facilitate the treatment, payment, and certain health care operations for health care provided to Valleywise Health
patients, and therefore wishes to allow External Entity to access EHR via the Valleywise Health EHR System subject to
the restrictions and other requirements set forth in this Agreement; and,
WHEREAS, External Entity provides professional and other medical services to Valleywise Health patients, but does
not otherwise have a contract with Valleywise Health for access to the Valleywise Health EHR System; and,
WHEREAS, External Entity has agreed to use the Valleywise Health EHR System to improve the quality and efficiency
of medical services External Entity provides to Valleywise Health patients, subject to the terms herein; and
NOW, THEREFORE, in consideration of the promises, the mutual agreements and covenants herein contained, and
other good and valuable consideration, the Parties agree as follows:
1. Definitions.
Authorized User: External Entity and its Authorized User are External Entity’s employed or contracted physician, nurse,
or other specifically identified and authorized person under this Agreement to use the Valleywise Health EHR System
to access Valleywise Health patient Electronic Health Records for a Permitted Use. Authorized Users are identified in
Exhibit A, attached hereto.
External Entity Administrator: External Entity shall also designate a liaison (“External Entity Administrator”) to
coordinate user access. The External Entity Administrator is responsible for managing the modification and termination
of accounts that the External Entity is granted.
Permitted Use: External Entity’s Permitted Use under this Agreement is limited to “Read Only Access” to the
Valleywise Health EHR System for the purpose of treatment, payment or certain health care operations. Notwithstanding
2
the foregoing, Permitted Use does not include selling or otherwise making commercial use of a EHR without the
Individual’s prior written consent as set forth in A.R.S. § 36-3805(B) or transferring data or de-identified health
information for the purpose of clinical research or as part of a set of data for an application for grant or other clinical
research funding with the Individual’s consent for the transfer as provided in A.R.S. § 36-3805(C).
2. Valleywise Health EHR System Access.
2.1
Subject to the terms and conditions of this Agreement, Valleywise Health hereby grants External Entity non-
transferable, non-delegable, and non-exclusive access to the Valleywise Health EHR System to permit Authorized Users
who require access to patient Electronic Health Records, as defined and set forth in Exhibit A attached hereto, to
electronically access and use the Valleywise Health EHR System solely to facilitate External Entity’s access to EHR for
a Permitted Use (the “System License”).
2.2
External Entity will identify and authenticate its Authorized Users, with the role of each Authorized User noted,
on Exhibit A. External Entity will ensure that each Authorized User participates in training on the requirements of this
Agreement. Authorized Users shall also complete Valleywise Health training on the use of Valleywise Health EHR as
required by Valleywise Health prior to the logon credentials being provided. Authorized Users will include only External
Entity’s staff members with whom External Entity has an employment or a contractual relationship and will be limited
to those who require access to the Valleywise Health EHR System to facilitate External Entity’s access for a Permitted
Use.
2.3
External Entity shall provide Valleywise Health with information for its Privacy Officer on Exhibit A and shall
properly notify Valleywise Health of any change to such contact.
2.4
External Entity Administrator may add Authorized Users with seven (7) day’s prior written notice to
Valleywise Health. External Entity Administrator must remove persons no longer Authorized Users by notifying the
Valleywise Health- Health Information Management Department not later than twenty-four (24) hours of change in
status by calling (602)344-5266. Furthermore, External Entity agrees to notify Valleywise Health in writing when
practicable but not later than twenty-four (24) hours after separation, when any Authorized User is separated from
employment or is no longer an agent of External Entity for any reason, including but not limited to termination or
voluntary separation. External Entity will notify Valleywise Health within twenty-four (24) hours when an Authorized
User’s role-based access to the Valleywise Health EHR System is no longer valid. External Entity further agrees to
validate that the Authorized Users listed in Exhibit A continue to require access to the System and continue to be
employees or agents of External Entity, thirty (30) days from the date of this Agreement and every thirty (30) days
thereafter. Exhibit A and/or any revisions to Exhibit A should be sent to Valleywise Health via email to
EHR.Access@valleywisehealth.org.
2.5
External Entity understands and warrants that EHR access and use shall be limited to that achieved through
unique access codes provided to each individual Authorized User by Valleywise Health, and that each Authorized User
shall be prohibited from using another authorized user’s access code to access and/or use the Valleywise Health EHR
System. Authorized User’s use of another authorized user’s access code to access and/or use the Valleywise Health EHR
System or provision of Authorized User’s access code to another person shall be considered a material breach of this
Agreement. External Entity further acknowledges and understands that Valleywise Health retains absolute control over
access to its EHR and that it may terminate individual Authorized Users’ access and/or the entire System License at any
time for any reason without penalty, regardless of any effect such termination may have on External Entity’s operations.
2.6
External Entity at its own expense and at no cost to Valleywise Health, will provide and maintain the hardware,
components, software, operating system(s), applications, network access, and interfaces necessary for External Entity to
access and use the Valleywise Health EHR System. External Entity is solely responsible for its own hardware, operating
system(s), network applications and interfaces to permit External Entity’s connection with the Valleywise Health EHR
System. Valleywise Health shall not be responsible for the procurement, installation or maintenance of any necessary
3
software, hardware and/or components, and Valleywise Health makes no representations or warranties regarding
External Entity’s software, hardware and/or components whatsoever.
3. Use or Disclosure of PHI.
3.1
External Entity shall not use or disclose any Protected Health Information (“PHI”) received from Valleywise
Health in any manner that would constitute a violation of federal or state law, including, but not limited to, HIPAA.
External Entity shall ensure that its directors, officers, employees, vendors, contractors, and agents use or disclose PHI
received from, or created and/or received on behalf of Valleywise Health only in accordance with the provisions of this
Agreement and federal and state law. External Entity further agrees that all information accessed through this Agreement
and through the Valleywise Health EHR System will be maintained in the strictest confidentiality and in the same manner
as the External Entity safeguards the confidentiality of its protected health information, or as required by state and federal
law. External Entity shall limit Authorized User access to only those persons or entities having a duly executed
HIPAA/HITECH Business Associate Agreement.
3.2
External Entity Authorized User will not further disclose any PHI in violation of this agreement.
4. External Entity Confidentiality Statement Requirement.
4.1
Before access to the Valleywise Health EHR System, each External Entity Authorized User shall read and agree
to the terms of the confidentiality statement (the “Confidentiality Statement—Terms and Conditions of Use”) in the form
provided herein as Exhibit B, attached hereto and incorporated herein by reference, as that form may be amended from
time to time. Before being granted access to the Valleywise Health EHR System, each Authorized User shall sign the
Confidentiality Statement – Terms and Conditions of Use and provide the executed document to Valleywise Health.
External Entity agrees to ensure that each Authorized User approved for access under this Agreement adheres to the
requirements of this Agreement and the Confidentiality Statement – Terms and Conditions of Use.
4.2
External Entity shall provide Valleywise Health with a group e-mail address to which Valleywise Health may
generate notices of records availability herein on Exhibit A. External Entity shall provide the e-mail address and direct
phone number of each Authorized User noted herein on Exhibit A. Exhibit A and/or any revisions to Exhibit A should
be sent to Valleywise Health via e-mail to EHR.Access@valleywisehealth.org.
5. Safeguards Against Unauthorized Use or Disclosure of Information.
5.1 External Entity agrees that it will implement all appropriate safeguards to prevent unauthorized use or disclosure
of PHI belonging to Valleywise Health. External Entity agrees to comply with all federal and state laws and regulations
regarding privacy, security, and electronic exchange of health information, as currently enacted or amended in the future.
External Entity agrees that it will not save or place Valleywise Health Confidential Information, including Valleywise
Health patient’s PHI, to portable media devices including, but not limited to, “Thumb Drives”, Memory Sticks, DVDs,
Floppies, CDs, PDAs, and other devices now known or hereinafter invented.
5.2 For purposes of this Agreement the term “Valleywise Health Confidential Information” includes but is not limited
to (i) all Valleywise Health technical, business and financial information including, without limitation, all information,
licenses, business plans, data, structures, models, techniques, and processes, or (ii) in the case of information given
verbally such information is disclosed in a manner such that a reasonable person would understand its confidential or
proprietary nature, or (iii) where the disclosure of such confidential or proprietary information would cause demonstrable
and material harm to Valleywise Health and would place Valleywise Health at a competitive disadvantage in the
marketplace.
4
6. Data Ownership.
External Entity acknowledges and agrees that Valleywise Health owns all rights, interests and title in and to its data,
including but not limited to PHI, and that such rights, interests and title shall remain vested in Valleywise Health at all
times. External Entity shall not compile and/or distribute analyses to third parties utilizing any data received from or
created or received on behalf of Valleywise Health without express prior written permission from Valleywise Health.
7. Reporting of Unauthorized Use or Disclosure of PHI.
7.1
External Entity shall, within twenty-four (24) hours of becoming aware or has reason to believe of an
unauthorized use or disclosure of Valleywise Health’ PHI by External Entity, any of its Authorized Users, and its officers,
directors, employees, vendors, contractors, agents or by a third party to which External Entity disclosed PHI, report any
such disclosure to Valleywise Health. Such notice shall be made to the following:
Valleywise Health:
Chief Compliance Officer
Valleywise Health
ADDRESS:
2601 E. Roosevelt Street, <NEW ADDRESS>
Phoenix, AZ 85008
PHONE:
(602)344-5915
Copy To:
Compliance Executive Assistant
Valleywise Health
ADDRESS:
2619 E. Pierce Street, 1st Floor
Phoenix, AZ 85008
E-Mail:
EHR.Access@valleysisehealth.org
7.2
Potential Data Security Breach. If at any time External Entity has reason to believe that PHI accessed, disclosed,
or transmitted pursuant to this Agreement may have been accessed or disclosed without proper authorization and contrary
to the terms of this Agreement, External Entity will immediately, but in no case more than twenty-four (24) hours, give
Valleywise Health notice and take actions to eliminate the cause of the breach. To the extent Valleywise Health deems
warranted, in its sole discretion, Valleywise Health will provide notice or require External Entity, at its sole cost and
expense, to provide notice to individuals whose PHI may have been improperly accessed or disclosed.
7.3
Valleywise Health has the right, at any time, to monitor, audit, and review External Entity’s activities and
methods in implementing this Agreement in order to assure compliance therewith, within the limits of External Entity’s
technical capabilities.
8. Third Party Access.
External Entity shall obtain the written approval from Valleywise Health prior to allowing any agent or subcontractor
access to PHI that is created and/or received on behalf of Valleywise Health. In the event that Valleywise Health consents
to such third-party access on a case-by-case basis, External Entity shall ensure that the agent or subcontractor agrees to
be bound by the same restrictions, terms and conditions that apply to External Entity through this Agreement. External
Entity shall require that any agent or subcontractor notify the External Entity of any instances in which PHI is used or
disclosed in an unauthorized manner. External Entity shall take steps to cure the breach of confidentiality and end the
violation and/or terminate the agency agreement or subcontract. External Entity and any authorized agent or designee
shall comply with Valleywise Health’ policies concerning access to PHI. Any entity presenting as a designee or
5
authorized agent of External Entity shall furnish to Valleywise Health such evidence of agency or engagement by
External Entity prior to any records being released to such entity, including a duly executed HIPAA/HITECH Business
Associate Agreement.
9. Maintenance and Availability of Books and Records.
For a period of ten (10) years after the termination or expiration of this Agreement, External Entity agrees to maintain
and make its internal practices, books and records relating to the use and disclosure of PHI received from Valleywise
Health, or created or received on behalf of Valleywise Health, available to Valleywise Health and to the Secretary of the
U.S. Department of Health and Human Services for purposes of determining Valleywise Health’ and External Entity’s
compliance with the HIPAA standards. External Entity promptly shall provide to Valleywise Health a copy of any
documentation that External Entity provides to the Secretary.
10. Investigations/Sanctions.
Valleywise Health reserves the right to monitor, review and investigate any External Entity activity under this
Agreement, including any reported and/or identified failures to comply with this Agreement and impose nonmonetary
appropriate sanctions. Sanctions may include, but are not limited to, the termination of this Agreement, termination of
External Entity’s access, or termination of any individual Authorized User access. External Entity agrees to cooperate
with all Valleywise Health investigations into whether terms of this Agreement have been violated. Failure to cooperate
can be considered a material breach and result in automatic termination of Authorized User access. Valleywise Health
reserves the right to report unprofessional conduct to appropriate licensing or other regulatory authorities. External
Entity agrees to cooperate with Valleywise Health in order to adequately investigate complaints received involving the
External Entity’s employees or agents. External Entity agrees to have a sanctions policy, produce it upon request, and
discipline their employees or agents for all breaches involving Valleywise Health PHI in accordance with the HIPAA
Privacy and Security Rule(s). External Entity understands that lack of adherence to this section allows Valleywise Health
to immediately terminate this Agreement and all associated access privileges.
11. Termination.
11.1
Immediate Termination. Valleywise Health may terminate its participation in this Agreement immediately
without liability for such termination, in the event Valleywise Health determines that External Entity, or External Entity’s
Authorized User, directors, officers, employees, vendors, contractors or agents have violated a material provision of this
Agreement.
11.2
Termination. Either party may terminate this Agreement without cause, upon thirty (30) days prior written
notice.
12. Limitation of Liability; Indemnification.
12.1
Limitation of Liability. Except as provided in Section 12.3, neither Valleywise Health nor External Entity will
be liable to the other for any special, incidental, exemplary, indirect, consequential or punitive damages (including loss
of use or lost profits) the extent arising out of or in connection with claims relating to Valleywise Health’ or External
Entity’s acts or omissions under this Agreement, including but not limited to claims, to the extent such claims arise from
any delay, omission or error in the transmission of PHI, provision or receipt of PHI, or the handling or storage of PHI,
or whether such liability arises from any claim based upon contract, warranty, tort (including negligence), product
liability or otherwise, and whether or not either party has been advised of the possibility of such loss or damage.
12.2
Release of Liability. Consistent with and notwithstanding any other provision in this Agreement to the contrary,
External Entity releases Valleywise Health from any claims arising out of the inaccuracy or incompleteness of the PHI
contained in the Valleywise Health EHR System except in cases arising out of Valleywise Health’ gross negligence.
6
External Entity also releases Valleywise Health from any claims relating to the clinical, medical or other decisions related
to the treatment of a patient, including those arising out of the unavailability of PHI through the Valleywise Health EHR
System, except for those arising out of Valleywise Health’ gross negligence.
12.3
Mutual Indemnification. Each party (as “indemnitor”) agrees to indemnify, defend and hold harmless
the other party (as “indemnitee”) from and against any and all claims, losses, liability, costs or expenses
(including reasonable attorney’s fees) (hereinafter collectively referred to as “claims”) arising out of bodily
injury of any person (including death) or property damage, but only to the extent that such claims, which result
in vicarious/derivative liability to the indemnitee, are caused by the act, omission, negligence, misconduct, or
other fault of the indemnitor, its officers, officials, agents, employees or volunteers.
13. Insurance.
External Entity shall maintain insurance coverage in amounts that will satisfy its indemnification obligation in this
Agreement, including but not limited to comprehensive general liability insurance, professional liability insurance (in
the minimum amount of $1,000,000 per claim and $3,000,000 in aggregate per year), errors and omission insurance,
directors and officers insurance, and HIPAA and cyber-security breach insurance in the amount of $5,000,000 in
aggregate per year. External Entity shall provide Valleywise Health evidence of such insurance upon request.
14. Privacy/HIPAA.
Valleywise Health and External Entity shall comply in all material respects with the standards for privacy and security
of protected health information of the Administrative Simplification subtitle of HIPAA and HITECH. Valleywise Health
and External Entity recognize their status as “covered entities” under HIPAA and agree to carry out their responsibilities
under this Agreement in accordance with such status.
15. Severability.
Any provision of this Agreement which is determined to be invalid, void or illegal shall in no way affect, impair or
invalidate any other provision hereof, and remaining provisions shall remain in full force and effect.
16. Entire Agreement.
This Agreement constitutes the entire agreement between the parties regarding access to Valleywise Health EHR System,
and supersedes all prior oral or written agreements, commitments, or understandings concerning the matters provided
for herein.
17. Amendment.
This Agreement may be modified only by a subsequent written Agreement executed by the parties. The provisions in
this Agreement may not be modified by any attachment, or letter agreement.
18. Governing Law.
This Agreement is governed by and interpreted in accordance with Arizona laws, without regard to its conflict of law
provisions. The Parties agree that jurisdiction over any action arising out of or relating to this Agreement shall be brought
or filed in the federal or state courts located in Maricopa County, Arizona.
7
19. Waiver.
Neither the waiver by any of the parties hereto of a breach of, or a default under any of the provisions of this Agreement,
nor the failure of either of the parties, on one or more occasions, to enforce any of the provisions of this Agreement or
to exercise any right or privilege hereunder, will thereafter be construed as a waiver of any subsequent breach or default
of a similar nature, or as a waiver of any of such provisions, rights or privileges hereunder.
20. Term.
This Agreement is effective as of the Effective Date listed above and will automatically renew after two (2) years from
the Effective Date for a period of one (1) years unless otherwise terminated by either party as provided for in Section
11.
21. Survival.
Unless expressly stated otherwise herein, the provisions and obligations contained in Paragraphs 5, 7, 8, 12, 13, 14, 18,
and 19 shall survive the termination or expiration of this Agreement for a period of five (5) years after the date of
expiration or termination.
[SIGNATURE PAGE TO FOLLOW]
8
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the date first above written.
Valleywise Health
By: ___________________________________
Printed Name: ___________________________
Title: __________________________________
Date: __________________________________
EXTERNAL ENTITY
IN WITNESS WHEREOF, the parties agree to enter into this Agreement:
FOR AND ON BEHALF OF MARICOPA COUNTY:
__________________________________
Bill Gates, Chairman, Board of Supervisors
_____________
Date
ATTEST:
__________________________________
Juanita Garza, Clerk of the Board
_____________
Date
APPROVED AS TO FORM:
__________________________________
Anne Longo, Attorney for Maricopa County
_____________
Date
9
Exhibit A
EXTERNAL ENTITY PRIVACY OFFICER CONTACT INFORMATION:
NAME: Joel Kodicek
PHONE: 602-506-6606
EMAIL: Joel.Kodicek@maricopa.gov
EXTERNAL ENTITY ADMINISTRATOR CONTACT INFORMATION:
NAME: _______________________________________
PHONE: ______________________________________
EMAIL: _______________________________________
LIST OF EXTERNAL ENTITY’S
AUTHORIZED USERS
Below is a list of the names of the persons who are External Entity’s Authorized Users and who are therefore
authorized to receive access to Valleywise Health PHI:
Name
Role
Phone
E-Mail
Designated External Entity group email address for Valleywise Health notices:
_________________________________
Exhibit A and/or any revisions to Exhibit A should be sent to Valleywise Health via e-mail to
EHR.Access@mihs.org.
10
Exhibit B
CONFIDENTIALITY STATEMENT
Terms & Conditions of Use
The protection of health and other confidential information, including but not limited to PHI, is a right protected
by law and enforced by fines, criminal penalties as well as policy. Safeguarding protected health information
(“PHI”) is a fundamental obligation for all persons accessing it. Your signature at the end of this statement will
commit you to that obligation and WILL be used as proof that you understand and agree to the stated basic duties
and facts regarding privacy.
Read it carefully.
Signing below indicates the following:
1. I agree to protect the privacy and security of confidential or protected health information I access through Valleywise
Health’ electronic health records (“EHR”) at all times.
2. I agree to
a) access EHR and/or PHI only to the minimum extent necessary for my assigned duties and
b) disclose such information only to persons authorized to receive it.
3. I understand and agree that:
a. Valleywise Health tracks all user IDs used to access electronic records. Those IDs enable discovery of
inappropriate access to patient records.
b. Inappropriate access and/or unauthorized release of confidential or PHI will result in disciplinary action, up to
and including termination of employment, and will result in a report to authorities charged with professional
licensing, enforcement of privacy laws and prosecution of criminal acts. I further understand and agree that
inappropriate access and/or unauthorized release of confidential or protected information may result in temporary
and/or permanent termination of my access to Valleywise Health electronic records.
c. I will be assigned a User ID and a one-time use activation code. I agree to immediately select and enter a new
password known only to me. I understand I may change my password at any time and will do so based on Valleywise
Health established policy and/or when prompted. I understand that I am to be the only individual using and in
possession of my confidential password. I am aware that the User ID and password are equivalent to my signature.
Also, I am aware that I am responsible for any use of the system utilizing my User ID and password. This includes
data entered, viewed, printed or otherwise manipulated. If I have reason to believe that my password has been
compromised, I will report this information to Valleywise Health, and I will also immediately change my password.
I understand that User IDs cannot be shared. Inappropriate use of my ID (whether by me or anyone else) is my
responsibility and exposes me to severe consequences.
4. I understand that PHI includes but is not limited to:
Any individually identifiable information in possession or derived from a provider of health care regarding a patient's
medical history, mental, or physical condition or treatment, as well as the patients and/or their family members
records, test results, conversations, research records and financial information. (Note: this information is defined in
the Privacy Rule as “protected health information.”). Examples include, but are not limited to:
11
-Physical medical and psychiatric records including paper, photo, video, diagnostic and therapeutic reports,
laboratory and pathology samples;
-Patient insurance and billing records;
-Centralized and/or department based computerized patient data (including any form of electronic storage
media).
External Entity Authorized User:
Signature: _____________________________________
Printed Name: __________________________________
Title:
Email: ________________________________________
Date:
DOB:
Location Address:
Work Phone: ____________________________________________________